CISCO has released patches for dozens of vulnerabilities in Secure Firewall Management Centre (FMC), Identity Services Engine (ISE) and Nexus Dashboard. The ISE update addresses 20 CVEs, including 12 rated critical. Three vulnerabilities — CVE-2026-20282, CVE-2026-20283 and CVE-2026-20284 — have been publicly disclosed and require administrative access to exploit. They could enable SQL injection, data tampering, arbitrary command execution, data access or modification, and denial-of-service attacks.
Cisco describes the first two as medium severity but high risk because the privileges they provide could potentially lead to root access.
The ISE fixes also cover three critical remote-code-execution flaws, two command-injection vulnerabilities that could provide root-level execution, an authentication bypass in the REST API, and other injection, cross-site scripting, information-disclosure and path-traversal issues. Cisco’s FMC updates address 18 CVEs, including eight critical flaws that could allow remote attackers to execute commands as root, gain root privileges or bypass protections and authentication.
Four grouped CVEs also affect Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defence. Cisco said two vulnerabilities in the class covered by CVE-2026-20332 — CVE-2026-20079 and CVE-2026-20316 — have been exploited in the wild since August, following disclosures in March and July.
Nexus Dashboard received fixes for six critical- and high-severity vulnerabilities involving authentication, code and command injection, cleartext storage, SQL injection and path traversal. Cisco also separately warned on Wednesday that a critical ISE authentication-bypass flaw was being exploited as a zero-day. Organisations using the affected products should review Cisco’s security advisories and apply the relevant updates.